News: 1611767610

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Command 'n' control botnet of notorious Emotet Windows ransomware shut down in multinational police raid

(2021/01/27)


EU police agency Europol has boasted of taking down the main botnet powering the Emotet trojan-cum-malware dropper, as part of a multinational police operation that included raids on the alleged operators’ homes in the Ukraine.

“To severely disrupt the EMOTET infrastructure, law enforcement teamed up together to create an effective operational strategy. It resulted in this week’s action whereby law enforcement and judicial authorities gained control of the infrastructure and took it down from the inside,” said Europol in a jubilant statement this afternoon.

[1]

Police forces from the Netherlands, Germany, the United States, the United Kingdom, France, Lithuania, Canada and Ukraine [2]all took part in the takedown.

“Analysis of accounts used by the group behind Emotet showed $10.5m being moved over a two-year period on just one Virtual Currency platform,” said Britain’s National Crime Agency, which [3]added : “NCA investigators were able to identify that almost $500,000 had been spent by the group over the same period to maintain its criminal infrastructure.”

[4]

According to the agency, the botnet was used to "infiltrate thousands of companies and millions of computers worldwide."

Ukrainian police published a remarkable YouTube video this afternoon, entirely in Ukrainian and embedded below, showing a raid on an alleged operator’s home. The video pictures dusty PCs and servers, large numbers of hard drives and (at about 1m50s) what looks like miniature gold bars.

[5]Youtube Video

What is Emotet and why is this a big deal?

Emotet is a frustratingly persistent email-delivered malware dropper [6]aimed at Windows machines . Intended targets are bombarded with emails containing Word documents as attachments. Once the mark is fooled into opening the attachment (typical lure themes include information about topical news such as COVID-19 statistics, supplier invoices and bank letters) and running macros embedded within it, the malware is deployed.

Originally Emotet itself was used for stealing online banking credentials, though later evolutions of it focused more on its ability to infect targets’ computers with any given malware.

The malware’s moneymaking potential hinged on that so-called dropper functionality: the criminals behind Emotet could rent it out to other malware or ransomware gangs. A common payload was [7]Trickbot , another banking trojan – which occasionally dropped the Ryuk ransomware.

Basically, Emotet was behind an awful lot of online badness – and if, as Britain’s NCA claimed, 700 of its command-and-control servers have been taken down, that should make a big dent in malware and ransomware infections.

Nigel Leary, deputy director of the NCA’s National Cyber Crime Unit, said in a statement: “Emotet was instrumental in some of the worst cyber attacks in recent times and enabled up to 70 per cent of the world’s malwares, including the likes of Trickbot and RYUK, which have had significant economic impact on UK businesses.

Good news for Emotet’s victims - you can see if you were infected

The Abuse.ch online [8]malware tracker showed very few known Emotet (aka Heodo, as that site calls the malware) nodes remaining online in the wake of the raids.

Europol also said the raids had resulted in innocent victims already infected with Emotet having those infections neutralised through police gaining control of the crims’ C2 infrastructure, explaining: "The infected machines of victims have been redirected towards this law enforcement-controlled infrastructure. This is a unique and new approach to effectively disrupt the activities of the facilitators of cybercrime."

Dutch police published an [9]Emotet email address checker (the page contains an English translation a few paragraphs in) so potential victims can check if they were known to have been infected by the nasty. This service appears to be powered by a seized list of email addresses known to the criminals behind the malware.

Professor Alan Woodward of the University of Surrey told The Register : "Europol were at the centre coordinating and just like the swoop on [10]Encrochat , this was another big blow to criminals using the internet to cause harm."

Alan Grau, VP of IoT and embedded solutions at Sectigo, said of the takedown: "The demise of Emotet will be welcomed in many quarters, but there is no doubt that malicious actors will be developing new variants to fill the vacuum. As such, email security practices, especially in light of remote work, are more important than ever.

"To protect against these ongoing attacks, enterprises must continue to train users on how to avoid phishing attacks. It is also critical to implement strong email security. Zero-touch deployment S/MIME email certificates automatically update the security profile of the email communication by authenticating the sender, encrypting the email content and attachment, and ensuring integrity."

Jordan LaRose, managing consultant at F-Secure, told The Reg : "Emotet has been a perennial enemy of businesses and cybersecurity practices alike for years now, and has contributed to some of the worst incidents we've ever seen.

"One of the most difficult aspects of incident response, and combating malware at large, is taking action against attackers who are able to act anonymously and largely without penalty due to the diplomatic implications of retaliation against them. This is never more true than with a botnet like Emotet that has infrastructure distributed among countries all over the world.

LaRose added: "While it is likely that other attackers will rise to fill the void left by Emotet, this investigation should serve as a warning to all other malware groups that distributed attack strategies won't protect them forever."

[11]

Criminal charges and prosecutions will doubtless follow from the raids. ®

Get our [12]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YBHwh@TcW5-PsMaqC6t6tQAAAAg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://www.europol.europa.eu/newsroom/news/world%E2%80%99s-most-dangerous-malware-emotet-disrupted-through-global-action

[3] https://www.nationalcrimeagency.gov.uk/news/nca-in-international-takedown-of-notorious-malware-emotet

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YBHwh@TcW5-PsMaqC6t6tQAAAAg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.youtube.com/watch?v=_BLOmClsSpc

[6] https://www.theregister.com/2020/02/10/emotet_spreads_over_wifi/

[7] https://search.theregister.com/?q=Trickbot

[8] https://feodotracker.abuse.ch/browse/heodo/

[9] https://www.politie.nl/themas/controleer-of-mijn-inloggegevens-zijn-gestolen.html

[10] https://www.theregister.com/2020/07/02/encrochat_op_venetic_encrypted_phone_arrests/

[11] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YBHwh@TcW5-PsMaqC6t6tQAAAAg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[12] https://whitepapers.theregister.com/

Doctor Syntax

"Criminal charges and prosecutions will doubtless follow from the raids."

I certainly hope so, and long sentences following those.

Throatwarbler Mangrove

Fuck that. It's time for summary executions, or at least extraordinary rendition. "You think you're so clever, Mr. Hacker? Meet your new best friend, Mr. Bone Saw."

(For the hyperbole-impaired: YES, THIS IS MEANT AS HYPERBOLE. Spare me your righteous indignation about extrajudicial punishment.)

Meh

Anonymous Coward

" The video shows dusty PCs and servers, large numbers of hard drives"

Meh,

this look remarkably similar to my room...

Several dusty desktop computers and monitors in every corner, dozens of hard drives and flash drives strewn about, multiple cellphones in various stages of disrepair and even an unused MacBook Air.

The only thing missing is the gold bars and cash.

Re: Meh

aregross

"this look remarkably similar to my room... blah blah

*The only thing missing is the gold bars and cash.*

You're doing it wrong

Mass Exodus From Hollywood

During the past week, over 150 Hollywood actors, musicians, writers,
directors, and key grips have quit their day jobs and moved to the Midwest
to engage in quieter occupations such as gardening or accounting. All of
the these people cite piracy as the reason for giving up their careers.

"I simply can't sit by and let my hard work be stolen by some snot nosed
punk over the Internet," explained millionaire movie director Steve
Bergospiel. "There's absolutely no incentive to create movies if they're
going to be transmitted at the speed of light by thousands of infringers.
Such criminal acts personally cost me hundreds -- no, thousands -- of
dollars. I can't take that kind of fear and abuse anymore."

MPAA President Pei Pervue considers the exodus to be proof that Hollywood
is waking up to the fact that they are being "held hostage" by copyright
infringers. "Without copyright protection and government-backed monopolies
on intellectual property, these's absolutely no reason to engage in the
creative process. Now the Internet, with its click-and-pirate technology,
makes it easy for anybody to flout the law and become a copyright
terrorist. With the scales tipped so much in favor of criminals, it's no
wonder some of Hollywood's elite have thrown in the towel. What a shame."